ChrisH Posted June 10, 2009 Sorry if I am not doing this correctly, but need help. I have run SuperAntiSpyware for some time and it always works. However, now I am unable to remove these two files. They are found and highlighted as problems, but every time I remove them and I reboot they are back. It is amazing that there is no reliable info on the entire internet on how to get rid of these. There are few sites coming up on Google, but they only want to sell me solutions and I don't trust the companies. Last thing I need to do is install another problem. Any help would be appreciated. Thanks, Chris Share this post Link to post Share on other sites
ChrisH Posted June 11, 2009 SUPERAntiSpyware Scan Log https://www.superantispyware.com Generated 06/10/2009 at 09:13 PM Application Version : 4.26.1002 Core Rules Database Version : 3933 Trace Rules Database Version: 1876 Scan type : Complete Scan Total Scan Time : 01:38:31 Memory items scanned : 476 Memory threats detected : 0 Registry items scanned : 5770 Registry threats detected : 23 File items scanned : 275886 File threats detected : 1 Adware.HBHelper HKLM\Software\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0} HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0} HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0} HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\InprocServer32 HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\InprocServer32#ThreadingModel HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\ProgID HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\TypeLib HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\VersionIndependentProgID HKCR\URLSearchHook.ToolbarURLSearchHook.1 HKCR\URLSearchHook.ToolbarURLSearchHook.1\CLSID HKCR\URLSearchHook.ToolbarURLSearchHook HKCR\URLSearchHook.ToolbarURLSearchHook\CLSID HKCR\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D} HKCR\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}\1.0 HKCR\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}\1.0\0 HKCR\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}\1.0\0\win32 HKCR\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}\1.0\FLAGS HKCR\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}\1.0\HELPDIR C:\PROGRAM FILES (X86)\RSTOOLBAR\RAPIDSHARE SEARCH BAR\TBHELPER.DLL Browser Hijacker.Deskbar HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B} HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32 HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version Share this post Link to post Share on other sites
cptwetleg Posted June 23, 2009 dear sir, I have the same sort of problem, after removal reboot,run scan they are back again, 4 times in 30mins. unable to paste as where you said to go is not on my version, hope this will do, interface\{4897bba6-48d9-468c-8efa-846275d770113}\ same except proxystubclsid\ same except sid32\ same except typelib\ repeat. these blighters need a dam good thrashing, they look like them illeagle immigrants to me, can they begone and go to the devil. hope you can help stefan, Share this post Link to post Share on other sites
RPHM2 Posted June 23, 2009 To find critical downloads, and to divert to the webpages you need try downloading apple's safari internet browser, or google chrome, these seem to be unaffected by traditional browser hi-jackers which normall affect fire-fox and Internet explorer Share this post Link to post Share on other sites
david1163rd Posted August 26, 2009 I have the same problem, I picked thus up from an external hardrive. How do I remove from both my computer and external hardrive? Thanks for any help SUPERAntiSpyware Scan Log https://www.superantispyware.com Generated 08/25/2009 at 09:18 PM Application Version : 4.25.1014 Core Rules Database Version : 4070 Trace Rules Database Version: 2010 Scan type : Complete Scan Total Scan Time : 01:04:14 Memory items scanned : 447 Memory threats detected : 0 Registry items scanned : 7176 Registry threats detected : 5 File items scanned : 41663 File threats detected : 9 Browser Hijacker.Deskbar HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B} HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32 HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version Adware.Tracking Cookie C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@2o7[1].txt C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@ad.yieldmanager[2].txt C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@ads.mail[1].txt C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@atdmt[1].txt C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@content.yieldmanager[1].txt C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@content.yieldmanager[2].txt C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@doubleclick[2].txt C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@find-assist[1].txt C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@wwwwp.find-assist[1].txt rnal hardrive. Here is my log Share this post Link to post Share on other sites
siliconman01 Posted August 26, 2009 david1163rd, If you are running Windows XP, Vista, or Windows 7 you should update SAS to the latest version which is V4.27.1002. Then be sure that you have the latest core/trace definitions. Reboot your computer into SAFE MODE and run a complete scan of system with SAS. Let it quarantine what it finds as infections. If that does not clear up the problem, then create a support request and let the SAS gurus help you fix the problem. https://www.superantispyware.com/precreateticket.html Share this post Link to post Share on other sites